Getting Data In

Using sedcmd to truncate QPM=

eoc
New Member

Hi Everyone,

Wondering if anyone has a solution to an issue I'm having truncating out some values we deem to be "junk".

We have Splunk indexing logs from AD security and I have the below sedcmd configured:

SEDCMD-shorternQPM = s/(.*QPM.*).*//g

Post restarting the indexer service I couldn't see any noticeable difference in the output.

Below is a snippet of the line where QPM exists:

QPM=

Tags (2)
0 Karma

somesoni2
Revered Legend

Are you looking to truncate part of your raw data or just drop the whole event itself (no indexing)? If it's the latter, I would suggest reading/implementing this:

https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Routeandfilterdatad#Filter_event_data_...

Your sample data and configuration entries will get truncated if you do not format them using "100010" button on top of the text editor in this page (or select and press Ctrl+K).

0 Karma

eoc
New Member

Hi Everyone,

Apologies, appears I hit a character limit.

We need most of the log file and need to omit a small component of it.

An example of a line we are attempting to clean can be seen below:

QPM=<root> <QPM id="the-one"> <public> <Options> <param name="sprPrmLockCount" value="2" /> <param name="sprPrmLockTimestamp" value="11.06.2016 20:36:31" /> <param name="sprPrmLocked" value="no" /> <param name="Layout" value="M|M|M|M|M" /> <param name="sprAnswersHashed" value="no" /> <param name="sprForceEnrollStartDate" /> <param name="sprInvalidQAProfile" value="no" /> <param name="sprLID" value="en" /> <param name="sprShortestAnswerSize" value="5" /> </Options> </public>

Any help is much appreciated

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What part do you need to omit?

---
If this reply helps you, Karma would be appreciated.
0 Karma

eoc
New Member

All of it from QPM to the end of the line

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You don't say which "QPM", but (QPM.*) should match everything from the first one.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You didn't give us much to work with.

The SEDCMD string is expecting a single character before "QPM", but the sample data has no such character. That's one possible explanation for the failure.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...